الحالة الحالية
الأبحاث ذات الصلة
٥- حملة رمز Drift من Salesforce جعلت موافقة OAuth حدودًا للمساءلة
كانت حملة Salesloft Drift ضد بيئات عملاء Salesforce عرضًا واضحًا لمشكلة المساءلة الحديثة في SaaS: لم يحتاج المهاجم إلى كسر الباب الأمامي لكل عميل. تمكن المهاجم من استخدام رموز OAuth الخاصة بتكامل موثوق به كسلطة مفوضة. جعل ذلك الموافقة والنطاقات وتخزين الرمز وحوكمة سوق التطبيقات ورؤية سجل العميل واستجابة الطرف الثالث للاختراق جزءًا من مساءلة Salesforce على الرغم من أن السجل العام يقول أن المشكلة لم تنشأ من ثغرة في منصة Salesforce الأساسية.
المقالة الرئيسيةمنشور 2026-07-10 - تخطط Salesforce لإطلاق أول مركز للذكاء الاصطناعي في لندن
أشارت Salesforce، عملاق البرمجيات، إلى أن سوق الذكاء الاصطناعي في المملكة المتحدة قد يتجاوز تريليون دولار بحلول 2035.
المقالة الرئيسيةمنشور 2026-05-26 - Salesforce's 2021 DNS outage made global deployment a continuity test
Salesforce said an emergency fix triggered a software issue and a DNS network incident in May 2021. The deeper accountability question is how a globally distributed change, process-restart behavior, recovery dependencies and service-level evidence combined to turn one intervention into a broad continuity failure.
المقالة الرئيسيةمنشور 2026-08-13 - Salesforce's 2019 Pardot permissions incident made recoverable authorization state a continuity obligation
Salesforce's 2019 Pardot permissions incident exposed a hard distinction between restoring a cloud service and restoring confidence in who may do what inside it. The public record supports a careful conclusion: authorization state is operational infrastructure, and continuity is unfinished until that state can be reconstructed, checked, and explained.
المقالة الرئيسيةمنشور 2026-08-13 - Salesforce's Drift-token campaign made OAuth consent an accountability boundary
The Salesloft Drift campaign against Salesforce customer environments was a clean demonstration of a modern SaaS accountability problem: the attacker did not need to break the front door of every customer. The attacker could use a trusted integration's OAuth access and refresh tokens as delegated authority. That made consent, scopes, token storage, app marketplace governance, customer log visibility, and third-party incident response part of Salesforce accountability even though the public record says the issue did not stem from a vulnerability in Salesforce's core platform.
المقالة الرئيسيةمنشور 2026-07-10
